2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-27378CRITICAL9.8AES contains a SQL injection vulnerability due to an inactive configuration that prevents the latest SQL parsing logic f...
CVE-2025-69766CRITICAL9.8Tenda AX3 firmware v16.03.12.11 contains a stack-based buffer overflow in the formGetIptv function due to improper handl...
CVE-2025-69763CRITICAL9.8Tenda AX3 firmware v16.03.12.11 contains a stack overflow in formSetIptv via the vlanId parameter, which can cause memor...
CVE-2025-69762CRITICAL9.8Tenda AX3 firmware v16.03.12.11 contains a stack overflow in formSetIptv via the list parameter, which can cause memory ...
CVE-2025-15521CRITICAL9.8The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to privilege e...
CVE-2025-55130CRITICAL9.1A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow-fs-write` restrictions u...
CVE-2025-56005CRITICAL9.8An undocumented and unsafe feature in the PLY (Python Lex-Yacc) library 3.11 allows Remote Code Execution (RCE) via the ...
CVE-2025-55423CRITICAL9.8A command injection vulnerability exists in the upnp_relay() function in multiple ipTIME router models because the contr...
CVE-2025-65482CRITICAL9.8An XML External Entity (XXE) vulnerability in opensagres XDocReport v0.9.2 to v2.0.3 allows attackers to execute arbitra...
CVE-2025-64087CRITICAL9.8A Server-Side Template Injection (SSTI) vulnerability in the FreeMarker component of opensagres XDocReport v1.0.0 to v2....
CVE-2025-36418CRITICAL9.8IBM ApplinX 11.1 is vulnerable due to a privilege escalation vulnerability due to improper verification of JWT tokens. A...
CVE-2025-14533CRITICAL9.8The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, a...
CVE-2025-55252CRITICAL9.8HCL AION  version 2 is affected by a Weak Password Policy vulnerability. This can  allow the use of easily guessable pas...
CVE-2025-55251CRITICAL9.8HCL AION is affected by an Unrestricted File Upload vulnerability. This can allow malicious file uploads, potentially re...
CVE-2025-52660CRITICAL9.8HCL AION is affected by an Unrestricted File Upload vulnerability. This can allow malicious file uploads, potentially re...
CVE-2025-11043CRITICAL9.1An Improper Certificate Validation vulnerability in the OPC-UA client and ANSL over TLS client used in Automation Studio...
CVE-2025-10484CRITICAL9.8The Registration & Login with Mobile Phone Number for WooCommerce plugin for WordPress is vulnerable to Authentication B...
CVE-2025-15403CRITICAL9.8The RegistrationMagic plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6...
CVE-2025-14894CRITICAL9.8Livewire Filemanager, commonly used in Laravel applications, contains LivewireFilemanagerComponent.php, which does not p...
CVE-2025-14510CRITICAL9.2Incorrect Implementation of Authentication Algorithm vulnerability in ABB ABB Ability OPTIMAX.This issue affects ABB Abi...
CVE-2025-59870CRITICAL9.8HCL MyXalytics  is affected by improper management of a static JWT signing secret in the web application, where the secr...
CVE-2025-60021CRITICAL9.8Remote command injection vulnerability in heap profiler builtin service in Apache bRPC ((all versions < 1.15.0)) on all ...
CVE-2025-62582CRITICAL9.8Delta Electronics DIAView has multiple vulnerabilities.
CVE-2025-62581CRITICAL9.8Delta Electronics DIAView has multiple vulnerabilities.
CVE-2025-65118CRITICAL9.3The vulnerability, if exploited, could allow an authenticated miscreant (OS Standard User) to trick Process Optimizatio...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now